Security1 distinct publisher2 min readPublished
SPEAKINGSTONE and DARKLANTERN both hand unauthenticated attackers root on ZBT-built hardware, and because neither advisory names a fixed firmware release, the remedy for an affected model is replacing it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
VulnCheck's own sinkhole produced the sharpest number in the disclosure and also the least representative one. SPEAKINGSTONE carries a hardcoded backup C2 domain that it reaches only where a primary server was never configured; the domain was unregistered, so VulnCheck registered it, stood up a reverse-engineered implementation of the protocol, and beacons began arriving as soon as the server was live [13]. By August 21, 392 unique devices had checked in, 390 of them in China [14], which leaves two outside it [2]. Of those, 363 self-reported the model L3_V2_8 on firmware 3.0.0.4.528 [15], or 92.6 percent of the sample [1]; 304 broadcast SSIDs beginning "CMCC" [15]; 83 percent sat on China Mobile's network [15], roughly 325 hosts [3]. Only units that were never given a primary C2 ever dial the backup, so the 392 is a floor drawn from an unrepresentative subset [16].
The version data is what turns this into a procurement decision. The advisory pages present affected builds as upper bounds, the CVE records name each firmware as a single exact build and set every other version's status to unknown, and no fixed release is named in either advisory [10]. An owner running a build outside the listed set has no published basis for deciding whether the implant is there.
Several entries in both CVE records sit under an unidentified vendor [17], so the published model lists are not the full set of names this firmware ships under. The Hacker News checked the IEEE-registered MAC prefix database on August 28 and found the blocks 78:A3:51 and F8:5E:3C both assigned to Shenzhen Zhibotong Electronics [12], and ZBT sells the same hardware and firmware to resellers that put their own name on the case [11]. The MAC address a device broadcasts identifies who built it more reliably than the brand printed on the case.
ENDLESSDOORS, the phone-home implant VulnCheck disclosed on August 5 in at least 20 Zbtlink models, is tracked as CVE-2026-66747 [9]. SPEAKINGSTONE's supported message types matter more than its CVSS rating: arbitrary command execution as root, exfiltration of the WAN PPPoE username and password, read and write access to a DNS hijack list, and a reverse SSH tunnel [5]. VulnCheck describes it as "a surveillance implant with root access to every device it runs on" [18]. The PPPoE credentials and the DNS list are the subscriber-facing attack; the tunnel is how an operator reaches whatever sits behind the router.
Ranked by verification strength, evidence, and original report placement.
VulnCheck disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each giving an unauthenticated remote attacker root command execution on affected devices.
VulnCheck said in its supply chain research: "This is a surveillance implant with root access to every device it runs on."
The implants were named SPEAKINGSTONE and DARKLANTERN by VulnCheck's zero-day research team and are tracked as CVE-2026-74232 and CVE-2026-74233 respectively.
VulnCheck, acting as CVE Numbering Authority, assigned both identifiers and rated each 9.3 on CVSS 4.0 and 9.8 on CVSS 3.1, with vectors recording a network attack requiring no privileges and no user interaction.
SPEAKINGSTONE runs as the service yunmgrd and sends beacons over UDP port 10000 to a hardcoded command-and-control server; because it dials outward it functions from behind NAT and ordinary egress filtering.
SPEAKINGSTONE's protocol supports message types that execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
security
Frontier AI can find the bugs faster. The patch queue is the number nobody published.1 distinct publisher
build
NIST answers an NVD audit with an AI tool nobody outside NIST has seen1 distinct publisher
security
CISA revises the Mitsubishi FA advisory a fourth time for one UDP denial-of-service bug1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete down to the hash, single in origin
The technical spine is unusually checkable: two service names, three UDP ports, three SHA-256 hashes, exact firmware strings, a named C2 domain. Nearly all of it originates with the party that found the implants, named them, assigned their identifiers and scored their severity. The Hacker News contributes three checks of its own — the IEEE prefix lookup tying 78:A3:51 and F8:5E:3C to Shenzhen Zhibotong, the primary C2 still resolving to an Alibaba Cloud address in Shenzhen on August 28, and the absence of all three identifiers from CISA's catalog version 2026.08.27 — and those are the only observations here not routed through the discloser. Our coverage holds that same report twice, which adds reach and no verification.
Two counts, neither of the population
Both numbers measure something narrower than "how many routers are exposed." The 203 hosts across 22 countries are machines that answered a probe, explicitly not machines found compromised. The 392 beacons are odder still: a device dials the backup domain only when no primary server was ever set, so the near-total concentration in China — 390 of 392, 363 of them one L3_V2_8 build, roughly 325 on China Mobile — describes the misconfigured tail rather than the installed base. Absent from all of it: units shipped, resellers served, and any evidence that a single owner has acted.
Careful arithmetic, one loose thread on exploitation
This reporting hedges where hedging costs it something: it labels the 203 as probe responders, calls the 392 a floor from an unrepresentative subset, and notes that the sinkhole only catches misconfigured units. The overshoot is narrower and sits in the exploitation record. DARKLANTERN appears in the discloser's own known-exploited catalog, whose criteria require public reports of exploitation in the wild, while CISA's enrichment of the same identifier the day before rates it proof-of-concept and CISA's catalog lists none of the three. "Factory implant" and "surveillance implant" are the discloser's characterisation; nothing published here establishes who wrote the code or who operates ac-link[.]com.
The discloser held every pen
One party found the implants, chose the codenames, assigned both CVE identifiers as a numbering authority, set the 9.3 and 9.8 scores, registered the abandoned backup C2 and ran the sinkhole that produced the only telemetry, then listed one of the two in the exploited-vulnerability catalog it sells. That does not make the work wrong — hashes and ports are testable by anyone who cares to. But no adversarial party appears anywhere in this story: no word from Shenzhen Zhibotong, no reseller, no second lab, and no regulator, since the government catalog operators actually queue from does not carry these identifiers.
Firm on how it works, soft on how far it reaches
Read this as high trust in the mechanics and low trust in the scale. The ports, services, hashes and authentication defects are specific enough to be falsified quickly if wrong, and the identification path via model number and MAC prefix is repeatable by any owner. Scale is where it thins: one publisher, published twice, relaying one vendor, with an exposure picture drawn from a skewed sinkhole and a probe count that the report itself declines to equate with compromise.